Security Tester (9 Month FTC)
Allwyn UK
| Company | Allwyn UK |
| Category | Security |
| Location | Watford |
| Remote | On-site (inferred) |
| Employment | Not stated |
| Level | Entry |
| Salary | Not stated by the employer |
| Posted | 20 May 2026 |
| Last verified | 3 Aug 2026 |
| Source | Employer ATS (workable) |
Description
At the heart of everything we do is our vision to change lives every day, and our mission to grow The National Lottery responsibly and champion its impact. We are Allwyn UK, part of the Allwyn Entertainment Group – a multi-national lottery operator with a market-leading presence across the USA (Michigan and Illinois) and Europe, including Czech Republic, Austria, Greece, Cyprus and Italy. While the main contribution of The National Lottery to society is through the funds to good causes, at Allwyn we put our purpose and values at the heart of everything we do. Join us as we embark on a once-in-a-lifetime, largescale transformation journey by creating a National Lottery that delivers more money to good causes. We’ll talk a bit more about us further down the page, but for now – let’s talk about the role and who we’re looking for… A bit about the role This role provides hands-on security testing across Allwyn's applications, cloud platforms and infrastructure. The main purpose of the role is to improve day-to-day testing coverage across web applications, APIs, backend services, cloud-hosted workloads, internal infrastructure and network-facing services, while supporting findings validation, remediation and retesting. This is an exciting opportunity to work within the national lottery and gain exposure to not just security testing across our technology stack but exposure to supporting both delivery and cyber defense. What you’ll be doing Security testing delivery Deliver security testing across web applications, REST APIs, backend services, cloudhosted workloads, internal infrastructure and network-facing services. Support testing of AWS and Azure environments, including common configuration weaknesses, access-control issues, exposed services and baseline cloud security concerns. Carry out testing across network and infrastructure layers, including host, service and exposure weaknesses where they affect enterprise risk. Support application-focused testing across web applications, APIs and backend services, including common issues around authentication, authorisation, input validation, session handling and data exposure. Use common security testing and validation tools to support manual testing, verification and basic assessment activity. Findings, remediation and incident support Investigate reported vulnerability findings where testing support is needed, help validate whether an issue is genuine, support teams with remediation advice, and retest fixes to confirm they are effective. Support security incidents where testing input is required, including helping assess technical impact, validate weaknesses and support follow-up testing. Produce clear, practical findings and support teams with remediation guidance that can be acted on. Support retesting, evidence collection, findings validation and tracking so that issues can be properly closed out. What experience we’re looking for Essential Hands-on experience in security testing across a mix of application, cloud, infrastructure or network environments. Working knowledge of web application testing, API testing and common backend-service security issues. Working knowledge of common application security frameworks and methodologies, including OWASP Top 10, OWASP API Security Top 10, secure authentication and authorisation patterns, and practical remediation approaches for common web and API weaknesses. Understanding of broader security testing approaches across applications, cloud and infrastructure, including vulnerability assessment, manual verification, configuration review and risk-based testing methods. Working knowledge of AWS and / or Azure, including common configuration and accesscontrol risks. Understanding of network and infrastruct